W3C

Edit comment LC-2085 for Mobile Web Best Practices Working Group

Quick access to

Previous: LC-2016 Next: LC-2032

Comment LC-2085
:
Commenter: Thomas Roessler <tlr@w3.org>

or
Resolution status:

Dom,

thanks for your request for review.

With respect to the guidelines regarding the rewriting of HTTPS
URIs, we notice that any such rewriting will break any use of TLS
for authenticating the client to the server (e.g., use of TLS client
certificates). Similarly, any applications on top of HTTPS that rely
on TLS channel bindings would detect the proxy's intervention as an
attack, and lead to a broken user experience; see RFC 5056 for more
details about channel bindings.

We recommend that you discuss this aspect with the IETF TLS Working
Group.

Regards,
(space separated ids)
(Please make sure the resolution is adapted for public consumption)


Developed and maintained by Dominique Hazaël-Massieux (dom@w3.org).
$Id: 2085.html,v 1.1 2017/08/11 06:43:20 dom Exp $
Please send bug reports and request for enhancements to w3t-sys.org